by Leo Feyer

Server-side request forgery (SSRF) via unvalidated RSS feed URLs

Date: 2026-07-13
CVE ID: CVE-2026-57232

Description

A backend user with access to the Feed Reader module can cause the server to fetch arbitrary internal URLs.

Affected versions

Contao 5.3.35 up to 5.3.47
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.8

Suggested solution

Upgrade to Contao 5.3.48 or 5.7.9.

Workaround

Disable the Feed Reader module.

More information

https://github.com/contao/contao/security/advisories/GHSA-87mg-5grr-rhwh